首页> 外国专利> Techniques for sharing network security event information

Techniques for sharing network security event information

机译:用于共享网络安全事件信息的技术

摘要

This disclosure provides techniques for pooling and searching network security events reported by multiple sources. As information representing a security event is received from one source, it is searched against a central or distributed database representing events reported from multiple, diverse sources (e.g., different client networks). Either the search or correlated results can be filtered and/or routed according at least one characteristic associated with the networks, for example, to limit correlation to events reported by what are presumed to be similarly situated networks. The disclosed techniques facilitate faster identification of high-relevancy security event information, and thereby help facilitate faster threat identification and mitigation. Various techniques can be implemented as standalone software (e.g., for use by a private network) or for a central pooling and/or query service. This disclosure also provides different examples of actions that can be taken in response to search results.
机译:本公开提供了用于汇集和搜索多个来源报告的网络安全事件的技术。作为从一个源接收到安全事件的信息,它被搜索到表示从多个不同源(例如,不同的客户端网络)报告的事件的中央或分布式数据库。可以根据与网络相关联的至少一个特征来筛选和/或传递搜索或相关结果,例如,限制与所预测的是类似的网络报告的事件的相关性。所公开的技术有助于更快地识别高相关安全性事件信息,从而有助于促进更快的威胁识别和缓解。各种技术可以实现为独立软件(例如,用于专用网络)或用于中央池和/或查询服务。本公开还提供了可以响应搜索结果采取的不同示例的示例。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号